Database/Firmware, BMC & network fabric
Supermicro BMC virtual media subsystem on X8STi-F with IPMI firmware 2.06: The researcher's own description
Impact
The researcher's own description is the operator-relevant one: a persistent backdoor on the BMC. Virtual media is the single most dangerous BMC feature to lose control of, because it is the mechanism by which an attacker attaches their own boot image to a node and reboots into it. Combined with command injection in the same subsystem, the attacker gets both code on the controller and the ability to boot the host into whatever they want - the complete out-of-band takeover, surviving any host-side remediation. Shell metacharacters in the ShareHost and ShareName fields of the /rpc/setvmdrive.asp handler reach a command interpreter on the controller.
Who can reach it
An authenticated attacker who can send HTTP requests to the BMC's IP address. Any valid BMC credential plus a route to the management network is sufficient.
What to do
This is legacy X8-generation hardware and firmware updates for it are effectively unavailable, so treat this as a case where flashing is not a real option. The controls that work are structural: disable virtual media on the BMC where the platform allows it, isolate these BMCs onto a management VLAN with no route from tenant or general corporate networks, and plan the hardware out. If X8-era Supermicro boards are still carrying production workloads, that is a fleet-lifecycle decision, not a patching decision.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.